1 results (0.001 seconds)
CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1
CVE-2023-47179 – WordPress WooODT Lite plugin <= 2.4.6 - Arbitrary Site Option Update vulnerability
https://notcve.org/view.php?id=CVE-2023-47179
31 Oct 2023 — Missing Authorization vulnerability in ByConsole WooODT Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through 2.4.6. The WooODT Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the byconsolewooodt_admin_fields_setting_files() function hooked via AJAX in versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with subscriber-level access an... • https://github.com/RandomRobbieBF/CVE-2023-47179 • CWE-862: Missing Authorization •